CVE-2026-16447
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php
CVSS
7.3
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 21, 2026 · Last modified: Jul 21, 2026 · CWE-284 · CWE-434
Not enough EPSS history yet.
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
- ucn9h68n9289.feishu.cnhttps://ucn9h68n9289.feishu.cn/docx/KttYdnLfzotGUSxx7p3cbaornPd?from=from_copylink
- vuldb.comhttps://vuldb.com/cve/CVE-2026-16447
- vuldb.comhttps://vuldb.com/submit/858466
- vuldb.comhttps://vuldb.com/vuln/380826
- vuldb.comhttps://vuldb.com/vuln/380826/cti
- www.dlink.comhttps://www.dlink.com/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-163327.3 HIG41.9%
——13A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.15hCVE-2026-163317.3 HIG50.2%
——15A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.17hCVE-2026-163307.3 HIG50.2%
——15A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.17hCVE-2026-163297.3 HIG41.9%
——13A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.17hCVE-2026-163277.3 HIG50.2%
——15A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.5hCVE-2026-555507.1 HIG9.4%
——3NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `admin` roles. However, in version 0.12.1, the MCP product tools expose the same write operations through `/api/mcp/mcp` using user-generated Bearer tokens and do not enforce role checks. Any authenticated low-privileged user who can generate an MCP API token can create, modify, archive, or soft-delete products in the shared CRM product catalog. Version 0.12.3 contains a fix.20h